The standard backing the Digital Trust Validation.
ESCODI-QRO-001 establishes the principles, criteria, and guidelines used by QRO. VERIFICADO to perform Digital Trust Validation processes in an objective, transparent, and verifiable manner.
🛡️ Administered by SGSD•✅ Applied by QRO. VERIFICADO•📄 Current Version ESCODI-QRO-001 V1.0•🔓 Public Document
Why does ESCODI exist?
Every organization conducting validation processes needs clear, uniform, and verifiable criteria. ESCODI was developed to ensure that all Digital Trust Validations are performed under the same principles, regardless of the evaluated business type.
This allows consistent, transparent processes based on objective evidence.
What does ESCODI represent?
The ESCODI-QRO-001 V1.0 standard establishes the minimum criteria for technical, operational, and legal evaluation used independently by QRO. VERIFICADO. Its purpose is to evaluate the level of digital trust, commercial transparency, the verifiable identity of the issuer, and basic technical security of businesses with an internet presence in the state of Querétaro.
Through this structured framework, safe and localizable commercial navigation is fostered, reducing information asymmetry and strengthening trust between digital consumers and local businesses.
Scope of Applicability
This standard is cross-cutting and can be voluntarily applied to evaluate and validate digital trust signals in:
🏢 Corporate Sites
Portals of companies or service providers presenting their profile, portfolio, and contact methods.
🛒 Online Stores
Websites equipped with a shopping cart, transactional catalogs, and payment gateways (E-commerce).
💻 Service Platforms
Interactive online software, SaaS platforms, and on-demand procedure or service portals.
Validation Evidence
The standard criteria may be accredited through documentary, technical, or functional evidence, depending on the nature of each requirement:
Whenever possible, public or technical verification mechanisms will be preferred over the request for additional documentation. The requested documentation must be proportional to the objective of the evaluated criterion and limited to the strictly necessary to issue an objective result.
Principle of Documentary Proportionality
The documentation required during the evaluation process must directly relate to the criterion it aims to accredit. When a requirement can be verified via technical evidence, public inquiry, or functional validation, this will be preferred over requesting additional documentation.
The Constancia de Situación Fiscal (CSF), licenses, permits, or other official documents may be accepted as accreditation media when pertinent, but they will not constitute the sole valid mechanism unless explicitly required by law or the nature of the criterion.
Hierarchy of Evidence
To guarantee the proportionality of the evaluation process, the standard will utilize the following order of preference to accredit its criteria:
Technical evidence: Obtained through website inspection, security analysis, or automated verification.
Public evidence: Obtained through registries, directories, Google Maps, official social networks, or other verifiable sources.
Functional evidence: Obtained through operational testing such as telephone calls, form submissions, emails, or functional checks.
Documentary evidence: Requested only when the previous types of evidence are insufficient to accredit the corresponding criterion.
Guiding Principles
The evaluation is guided by six fundamental principles:
⚖️ Legitimacy
The existence of the business and the identity of the solicitor must be verifiable through sufficient evidence in line with the nature of the organization.
👁️ Transparency
The site must provide clear information about its ownership, contact channels, applicable policies, and conditions of operation when applicable.
🔒 Security
The site must implement technical mechanisms that protect the confidentiality, integrity, and availability of information, including the use of HTTPS and basic security controls.
🛡️ Privacy
Personal data processing must comply with current legislation and adopt reasonable measures to protect the information provided by users.
🔍 Objectivity
All evaluations must be based on verifiable technical, documentary, or functional evidence, avoiding subjective criteria.
📂 Data Minimization
During the evaluation process, only the documentation strictly necessary to accredit each criterion of the standard will be requested, prioritizing verification mechanisms that reduce the collection of personal data.
How is the standard applied?
The integration of the standard with the trust ecosystem follows a clear timeline:
When all businesses are evaluated using the same criteria, decisions stop depending on opinions and start depending on verifiable evidence.
⚖️ Uniformity
All processes use exactly the same evaluation criteria.
👁️ Transparency
Criteria are public and can be consulted by anyone.
📋 Consistency
Each validation follows the same methodology regardless of the evaluated business.
📈 Evolution
The standard can be updated to incorporate new technologies and best practices.
"A standard protects both the evaluated business and the consumer because it establishes clear rules before starting any validation process."
Standard Areas of Evaluation
The verification process evaluates compliance structured into five digital trust pillars:
Pillar ITechnical Security & Navigation
▼
Verifies that the website infrastructure provides a basic security layer to safeguard user navigation and data transmission:
Active and valid SSL certificate: Mandatory SSL/TLS connection encryption.
HTTPS navigation: Forced redirection to prevent insecure connections (HTTP).
Absence of malware or safety alerts: No critical detections in browsers or web reputation databases.
Availability and stable loading: The website must respond adequately to public requests.
Pillar IIIdentity & Local Operation
▼
Verifies the identity of the solicitor and confirms the actual physical existence and location of the business or independent professional behind the digital platform:
Identity and Representation of the Solicitor:
Objective: Verify who requests the validation and their link to the business.
Acceptable Evidence:
Official identification (INE / Passport) of the legal representative or owner, power of attorney or linking documentation, official emails, corporate records, or other technical or administrative evidence.
Physical Location of the Business:
Objective: Verify that the business operates from a real and verifiable location.
Acceptable Evidence:
Google Maps, Street View, commercial/public records, business directories, photograph of the premises, commercial utility bill (when needed), video call verification, or on-site validation.
Pillar IIIVerified Contact Methods
▼
Ensures that the visitor has direct and real communication channels with the business, preventing information isolation:
Operational telephone line: Telephone number validated via call or active support channel.
Support email: Address under its own domain or verified official mailbox with an active response rate.
Interactive customer service: Direct messaging, web chats, or forms with prompt responses.
Pillar IVLegal & Regulatory Transparency
▼
Validates strict compliance with basic regulations regarding digital consumer rights and data protection:
Mandatory Privacy Notice: Drafted in compliance with the Personal Data Protection Law (LFPDPPP).
Terms & Conditions of Use: Clear policies on site use, legal limitations, and commercial scope.
Service transparency: Clear statements about service scope, validity, and commitments.
Pillar VCommercial Integrity (E-commerce)
▼
Additional mandatory evaluation criteria exclusive to transactional sites and online stores:
Total price transparency: Explicit breakdown of costs, applicable taxes, shipping, and surcharges.
Cancellation and return policies: Clear and legible wording of the refund or exchange process.
After-sales information: Active channels for tracking purchases, deliveries, and claims resolution.
Application Principles
The criteria defined in this standard are applied based on four foundational principles:
⚖️ Uniformity
All businesses are evaluated under the same criteria and rules, ensuring equal treatment.
🔍 Objectivity
All findings, results, and evaluations are strictly based on technical and documentary evidence.
📂 Traceability
Each validation maintains verifiable history and records on public server dossiers.
📈 Continuous Improvement
The standard evolves dynamically according to emerging technological security challenges.
Results, Evidence, and Validity
Businesses evaluated under the ESCODI-QRO-001 V1.0 standard receive a validation result of Approved, Approved with Observations, or Not Approved. Approved sites obtain their respective Digital Trust Seal, a public record on our servers, a unique validation folio, and a digital validation certificate in PDF backed by a SHA-256 cryptographic signature.
Validation has an ordinary and non-extendable validity of 12 months from its issuance. Upon expiration, a full re-evaluation must be performed to ensure continuous maintenance of the standard policies. Automated monitoring may detect relevant changes in the availability, basic security, and operational status of the validated site.
Standard Government
ESCODI-QRO-001 is part of the technical governance system administered by SGSD and used by QRO. VERIFICADO to conduct Digital Trust Validation processes.
Future versions of the standard will be documented and published as the ecosystem needs evolve.
Limitations and Legal Disclaimer
⚠️ Important Validation Criteria
Not a government certification: QRO. VERIFICADO is a commercially independent, private technical evaluation entity. This badge does not replace any permit, license, or authorization from local, state, or federal government authorities.
Does not replace legal obligations: It is the sole responsibility of the validated business to comply with all legal, tax, consumer protection (PROFECO), and data protection regulations applicable to its sector.
Temporary Guarantee: The seal validates compliance with the criteria defined in this standard only at the time of evaluation and does not exempt the business from future technical incidents, hacks, or bad business practices.
Standard Governance Model
The standard governance structure ensures technical autonomy and consistency:
SGSD
➔
ESCODI
➔
QRO. VERIFICADO
➔
Validations
➔
Verified Businesses
Version History
Historical and current revisions of the ESCODI standard:
Version
Release Date
Description
Status
ESCODI-QRO-001 V1.0
2025-10-15
Initial baseline release of the standard.
✓ Current Active
"A standard builds trust when its criteria are clear, uniform, and applied in a consistent manner."